Skip to content

ci: bump typing-extensions test pin to 4.16.0 - #3928

Merged
MohammadHaroonAbuomar merged 1 commit into
mainfrom
mhabuomar/ci-typing-extensions-4160
Sep 13, 2026
Merged

MohammadHaroonAbuomar merged 1 commit into
mainfrom
mhabuomar/ci-typing-extensions-4160

Conversation

@MohammadHaroonAbuomar

Copy link
Copy Markdown
Collaborator

Related Issue

None. Splits the one-line CI fix out of #3919 so it can land on its own.

Problem & Solution

Problem: CI on main has failed test (agent-os, 3.11–3.13) and test (agent-mesh, 3.11–3.13) on every run since 2026-09-08. anyio 4.15.0 (released 2026-09-02) imports typing_extensions.sentinel, which exists only from typing-extensions 4.16.0. The test jobs install the package (resolving 4.16.0) and then install requirements/ci-test.txt, whose typing-extensions==4.15.0 pin downgrades it. Every test module that imports fastapi fails at collection:

ImportError: cannot import name 'sentinel' from 'typing_extensions'

Solution: raise the pin to 4.16.0 with the PyPI wheel hash, and leave a comment explaining the constraint.

Impact on Your Work

Unblocks CI for every open PR and for the dependabot lane (15 routine PRs are held only by this failure).

Timeline

None

Alternatives Considered

Pin anyio<4.15 in agent-os and agent-mesh: rejected, it caps a runtime dependency to work around a test-only constraints file.

Type of Change

  • Maintenance (dependency updates, CI/CD, refactoring)

Package(s) Affected

  • docs / root

Testing

Unit Testing

N/A, pin change only.

Manual Testing

  • pip install --require-hashes -r agent-governance-python/requirements/ci-test.txt into a scratch target installs 4.16.0 and typing_extensions.sentinel resolves.
  • anyio 4.15.1 with typing-extensions 4.16.0: import anyio.abc succeeds.
  • Hash matches the PyPI-published digest for typing_extensions-4.16.0-py3-none-any.whl.

Checklist

  • I have linked a related issue above, or completed "Problem & Solution", "Impact on Your Work", and "Alternatives Considered"
  • My code follows the project style guidelines (ruff check)
  • I have added tests that prove my fix/feature works
  • All new and existing tests pass (pytest)
  • I have updated documentation as needed
  • I have signed the Microsoft CLA

Attribution & Prior Art

  • This contribution does not contain code copied or derived from other projects without attribution
  • Any external projects that inspired this design are credited in code comments or documentation
  • If this PR implements functionality similar to an existing open-source project, I have listed it below

AI Assistance

  • I can explain every meaningful change in this PR: what it does, why, and what tradeoffs were considered
  • I have run tests and verification appropriate for this change
  • No part of this PR was autonomously submitted by an AI agent without my review
  • I have not used AI to generate review comments on others' PRs

IP, Patents, and Licensing

  • This contribution does not implement patent-pending or patent-encumbered techniques
  • This contribution does not require an NDA or licensing agreement to understand or use
  • Any AI tools used have terms compatible with the MIT License

anyio 4.15.0 (2026-09-02) imports typing_extensions.sentinel, which
only exists from typing-extensions 4.16.0. The agent-os and agent-mesh
test jobs install the package (resolving typing-extensions 4.16.0),
then install requirements/ci-test.txt, whose 4.15.0 pin downgrades it.
Every test module that imports fastapi then fails at collection with
ImportError: cannot import name 'sentinel'. CI on main has been red on
test (agent-os, 3.11-3.13) and test (agent-mesh, 3.11-3.13) since
2026-09-08 for this reason.

Raise the pin to 4.16.0 (hash from PyPI) and note why next to it.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
pip/typing-extensions 4.16.0 UnknownUnknown

Scanned Files

  • agent-governance-python/requirements/ci-test.txt

@github-actions github-actions Bot added the size/XS Extra small PR (< 10 lines) label Sep 10, 2026
@github-actions

Copy link
Copy Markdown

PR Review Summary

Check Status Details
🔍 Code Review ⚠️ Missing No current-run comment
🛡️ Security Scan ⚠️ Missing No current-run comment
🔄 Breaking Changes ⚠️ Missing No current-run comment
📝 Docs Sync ⚠️ Missing No current-run comment
🧪 Test Coverage ⚠️ Missing No current-run comment

Verdict: ⚠️ AI review incomplete; ready for human review

AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims.

@MohammadHaroonAbuomar
MohammadHaroonAbuomar merged commit 818ea72 into main Sep 13, 2026
129 checks passed
@MohammadHaroonAbuomar
MohammadHaroonAbuomar deleted the mhabuomar/ci-typing-extensions-4160 branch September 13, 2026 16:50
Karim Mehalebi (karimad) pushed a commit to karimad/agent-governance-toolkit that referenced this pull request Sep 14, 2026
anyio 4.15.0 (2026-09-02) imports typing_extensions.sentinel, which
only exists from typing-extensions 4.16.0. The agent-os and agent-mesh
test jobs install the package (resolving typing-extensions 4.16.0),
then install requirements/ci-test.txt, whose 4.15.0 pin downgrades it.
Every test module that imports fastapi then fails at collection with
ImportError: cannot import name 'sentinel'. CI on main has been red on
test (agent-os, 3.11-3.13) and test (agent-mesh, 3.11-3.13) since
2026-09-08 for this reason.

Raise the pin to 4.16.0 (hash from PyPI) and note why next to it.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
Yuvraj Singh (yuvrajsingh2428) pushed a commit to yuvrajsingh2428/agent-governance-toolkit that referenced this pull request Oct 1, 2026
anyio 4.15.0 (2026-09-02) imports typing_extensions.sentinel, which
only exists from typing-extensions 4.16.0. The agent-os and agent-mesh
test jobs install the package (resolving typing-extensions 4.16.0),
then install requirements/ci-test.txt, whose 4.15.0 pin downgrades it.
Every test module that imports fastapi then fails at collection with
ImportError: cannot import name 'sentinel'. CI on main has been red on
test (agent-os, 3.11-3.13) and test (agent-mesh, 3.11-3.13) since
2026-09-08 for this reason.

Raise the pin to 4.16.0 (hash from PyPI) and note why next to it.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
Signed-off-by: yuvrajsingh2428 <offcyuvi2428@gmail.com>
MinYi Xie (ppcvote) added a commit to ppcvote/agent-governance-toolkit that referenced this pull request Oct 4, 2026
anyio>=4.15 imports typing_extensions.sentinel, which only exists from
typing-extensions 4.16.0. The integration install resolves 4.16.0, but the
hash-pinned ci-test.txt step then downgrades it to 4.15.0, so importing
openai-agents (via mcp -> anyio) fails at test collection in
test-integrations (openai-agents-trust).

Mirrors upstream microsoft#3928.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/XS Extra small PR (< 10 lines)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant